CLAIMS 

What is claimed is: 

1 1 . A method of analysis of access list subsumption in routing devices of an actual or 

2 planned routed computer network, comprising: 

3 producing structured data in electronic memory which includes respective stored router 

4 names and respective stored access lists which respectively include elements with 

5 address/mask pairs, and wherein said structured data associates respective access 

6 lists with respective router names; 

7 determining whether respective access lists in the structured data include two or more 
S 8 elements in which a first element in the access list has a more general or equal 
5.1.9 address/mask pair than a second element in the access list, wherein the respective 

i 

{JO access lists are structured such that the first element is encountered prior to the 

IHI second element during typical processing of the respective access lists; and 

C$2 storing in electronic memory a report of access list elements in which a first element in 

f#3 the access list has a more general or equal address/mask pair than a second 

jW element in the access list 

1 2. The method of claim 1 wherein one or more of the respective stored access lists are 

2 respectively related to input packets and one or more of the respective stored access lists 

3 are respectively related to output packets and wherein the step of producing structured 

4 data is based at least in part on the respective stored access lists. 

1 3. The method of claim 1 wherein each of the respective stored access lists is related to a 

2 respective level three protocol and wherein the step of producing structured data is based 

3 at least in part on the respective stored access lists. 
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The method of claim 3 wherein the respective level three protocol is one from a group 
consisting of IP, IPX, and AppleTalk and wherein the step of producing structured data is 
based at least in part on the respective stored access lists. 

A method of identifying network integrity violations in a computer network, comprising: 
producing structured data in electronic memory which includes respective stored router 
names and respective stored access lists which respectively include patterns used 
to filter data into and out of a routing device, and wherein said structured data 
associates respective access lists with respective router names; 
determining whether respective access lists in the structured data include a subsumption 
relation in which a first pattern is more general than or equal to a second pattern, 
wherein the respective access lists are structured such that the first pattern is 
encountered prior to the second pattern during typical processing of the respective 
access lists; and 

storing in electronic memory a list of subsumption relations identifying respective pairs 
of first and second patterns. 

The method of claim 5 wherein one or more of the respective stored access lists are 
respectively related to input packets and one or more of the respective stored access lists 
are respectively related to output packets and wherein the step of producing structured 
data is based at least in part on the respective stored access lists. 

The method of claim 5 wherein each of the respective stored access lists is related to a 
respective level three protocol and wherein the step of producing structured data is based 
at least in part on the respective stored access lists. 
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8 . The method of claim 7 wherein the respective level three protocol is one from a group 
consisting of IP, IPX, and AppleTalk and wherein the step of producing structured data is 
based at least in part on the respective stored access lists. 

9. A computer-readable medium carrying one or more sequences of instructions for 
analyzing access list subsumption in routing devices of an actual or planned routed 
computer network, which instructions, when executed by one or more processors, cause 
the one or more processors to carry out the steps of: 

producing structured data in electronic memory which includes respective stored router 
names and respective stored access lists which respectively include elements with 
address/mask pairs, and wherein said structured data associates respective access 
lists with respective router names; 

determining whether respective access lists in the structured data include two or more 
elements in which a first element in the access list has a more general or equal 
address/mask pair than a second element in the access list, wherein the respective 
access lists are structured such that the first element is encountered prior to the 
second element during typical processing of the respective access lists; and 

storing in electronic memory a report of access list elements in which a first element in 
the access list has a more general or equal address/mask pair than a second 
element in the access list. 

1 0. The computer-readable medium of claim 9 wherein one or more of the respective stored 
access lists are respectively related to input packets and one or more of the respective 
stored access lists are respectively related to output packets and wherein the instructions 
cause the one or more processors to carry out the step of producing structured data based 
at least in part on the respective stored access lists. 
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11. The computer-readable medium of claim 9 wherein each of the respective stored access 
lists is related to a respective level three protocol and wherein the instructions cause the 
one or more processors to carry out the step of producing structured data based at least in 
part on the respective stored access lists. 

1 2. The computer-readable medium of claim 1 1 wherein the respective level three protocol is 
one from a group consisting of IP, IPX, and AppleTalk and wherein the instructions 
cause the one or more processors to carry out the step of producing structured data based 
at least in part on the respective stored access lists. 

13. A computer-readable medium carrying one or more sequences of instructions for 
identifying network integrity violations in a computer network, which instructions, when 
executed by one or more processors, cause the one or more processors to carry out the 
steps of: 

producing structured data in electronic memory which includes respective stored router 
names and respective stored access lists which respectively include patterns used 
to filter data into and out of a routing device, and wherein said structured data 
associates respective access lists with respective router names; 

determining whether respective access lists in the structured data include a subsumption 
relation in which a first pattern is more general than or equal to a second pattern, 
wherein the respective access lists are structured such that the first pattern is 
encountered prior to the second pattern during typical processing of the respective 
access lists; and 

storing in electronic memory a list of subsumption relations identifying respective pairs 
of first and second patterns. 
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14. The computer-readable medium of claim 13 wherein one or more of the respective stored 
access lists are respectively related to input packets and one or more of the respective 
stored access lists are respectively related to output packets and wherein the instructions 
cause the one or more processors to carry out the step of producing structured data based 
at least in part on the respective stored access lists. 

15. The computer-readable medium of claim 13 wherein each of the respective stored access 
lists is related to a respective level three protocol and wherein the instructions cause the 
one or more processors to carry out the step of producing structured data based at least in 
part on the respective stored access lists. 

16. The computer-readable medium of claim 15 wherein the respective level three protocol is 
one from a group consisting of IP, IPX, and AppleTalk and wherein the instructions 
cause the one or more processors to carry out the step of producing structured data based 
at least in part on the respective stored access lists. 

17. An apparatus for analyzing access list subsumption in routing devices of an actual or 
planned routed computer network, comprising: 

means for producing structured data in electronic memory which includes respective 

stored router names and respective stored access lists which respectively include 
elements with address/mask pairs, and wherein said structured data associates 
respective access lists with respective router names; 

means for determining whether respective access lists in the structured data include two 
or more elements in which a first element in the access list has a more general or 
equal address/mask pair than a second element in the access list, wherein the 
respective access lists are structured such that the first element is encountered 
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prior to the second element during typical processing of the respective access 
lists; and 

means for storing in electronic memory a report of access list elements in which a first 
element in the access list has a more general or equal address/mask pair than a 
second element in the access list. 

18. An apparatus for identifying network integrity violations in a computer network, 
comprising: 

means for producing structured data in electronic memory which includes respective 

stored router names and respective stored access lists which respectively include 
patterns used to filter data into and out of a routing device, and wherein said 
structured data associates respective access lists with respective router names; 

means for determining whether respective access lists in the structured data include a 
subsumption relation in which a first pattern is more general than or equal to a 
second pattern, wherein the respective access lists are structured such that the first 
pattern is encountered prior to the second pattern during typical processing of the 
respective access lists; and 

means for storing in electronic memory a list of subsumption relations identifying 
respective pairs of first and second patterns. 

19. An apparatus for analyzing access list subsumption in routing devices of an actual or 
planned routed computer network, comprising: 

a network interface coupled to the routed computer network for receiving one or more 
packet flows therefrom; 
a processor; 
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one or more stored sequences of instructions which, when executed by the processor, 

cause the processor to carry out the steps of: 

producing structured data in electronic memory which includes respective stored 
router names and respective stored access lists which respectively include 
elements with address/mask pairs, and wherein said structured data 
associates respective access lists with respective router names; 
determining whether respective access lists in the structured data include two or 
more elements in which a first element in the access list has a more 
general or equal address/mask pair than a second element in the access 
list, wherein the respective access lists are structured such that the first 
element is encountered prior to the second element during typical 
processing of the respective access lists; and 
storing in electronic memory a report of access list elements in which a first 

element in the access list has a more general or equal address/mask pair 
than a second element in the access list. 

20. An apparatus for identifying network integrity violations in a computer network, 
comprising: 

a network interface coupled to the routed computer network for receiving one or more 
packet flows therefrom; 
a processor; 

one or more stored sequences of instructions which, when executed by the processor, 
cause the processor to carry out the steps of: 

producing structured data in electronic memory which includes respective stored router 
names and respective stored access lists which respectively include patterns used 
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to filter data into and out of a routing device, and wherein said structured data 
associates respective access lists with respective router names; 
determining whether respective access lists in the structured data include a subsumption 
relation in which a first pattern is more general than or equal to a second pattern, 
wherein the respective access lists are structured such that the first pattern is 
encountered prior to the second pattern during typical processing of the respective 
access lists; and 

storing in electronic memory a list of subsumption relations identifying respective 
pairs of first and second patterns. 
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